[UPDATE] [hoch] MISP: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in MISP ausnutzen, um Sicherheitsmechanismen zu umgehen, Informationen offenzulegen, Daten oder Sitzungen zu manipulieren und die Verfügbarkeit zu beeinträchtigen.
CSIRTS triage
- What
- Multiple vulnerabilities in MISP allow attackers to bypass security controls, disclose information, manipulate threat data and sessions, and impair availability.
- Who is affected
- MISP threat intelligence sharing instances, particularly those federated or exposed for remote collaboration.
- Urgency
- High priority because MISP is critical security infrastructure; compromise enables threat intelligence poisoning, data exfiltration, and denial of service affecting entire threat intelligence ecosystem.
- Action
- Apply security patches from the MISP project immediately and audit user access, session data, and imported threat intelligence for signs of compromise.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch MISP
Get an email when a new MISP advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3173
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-852160.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-852210.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-852260.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-852270.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-852300.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-852360.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-852370.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-852380.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-852390.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-855330.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-85216 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85221 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85226 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85227 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85230 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85236 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85237 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85238 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85239 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85533 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85538 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85546 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiples vulnérabilités dans MISP (14 septembre 2026)cert-fr-avis
- unknownCVE-2026-85546: MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edi…nvd
- unknownCVE-2026-85538: An incorrect authorization vulnerability in MISP allowed authenticated users to delete attribu…nvd
- unknownCVE-2026-85533: An authorization flaw in MISP allowed an authenticated user to submit a sharing_group_id witho…nvd
- unknownCVE-2026-85239: A vulnerability in MISP's event template handling allowed an authenticated user with permissio…nvd
- unknownCVE-2026-85238: MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom conf…nvd
- unknownCVE-2026-85237: A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an a…nvd
- unknownCVE-2026-85236: A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MIS…nvd
- unknownCVE-2026-85230: A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget conf…nvd
- unknownCVE-2026-85227: MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filt…nvd
- unknownCVE-2026-85226: MISP contains an authorization flaw in the OnDemand correlation engine where correlations were…nvd
- unknownCVE-2026-85221: MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClie…nvd
Recent advisories for MISP
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-92003: Affected versions of MISP do not consistently apply the existing authentication-failure loggin…nvd · 2026-09-15
- unknownCVE-2026-92002: Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. T…nvd · 2026-09-15
- high[NEU] [hoch] MISP: Mehrere Schwachstellencert-bund · 2026-09-15
- unknownCVE-2026-91859: Affected versions of MISP can record incorrect access-log data for requests that terminate in …nvd · 2026-09-15
- unknownCVE-2026-91857: Affected versions of MISP expose several state-changing controller actions without restricting…nvd · 2026-09-15
- unknownCVE-2026-91851: Affected versions of MISP incorrectly filter dashboard templates that are restricted to a spec…nvd · 2026-09-15
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service2026-09-15
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen2026-09-15
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff2026-09-15
- high[NEU] [hoch] MISP: Mehrere Schwachstellen2026-09-15
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service oder unspezifischer Angri…2026-09-15